Enterasys-networks 9034385 Manuel d'utilisateur Page 30

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 98
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 29
Model 3: End-System Authorization with Assessment
2-8 NAC Deployment Models
ARADIUSserverisonlyrequiredifoutofbandnetworkaccesscontrolusingtheNACGateway,
orinlinenetworkaccesscontrolusingtheLayer2NACController,isimplementedwithweb
basedand/or802.1Xauthenticati on.
NetSightPolicyManagerisrequiredforallinlineNACdeployments,andrecommendedforout
of
bandNACdeploymentsthatutilizeEnterasyspolicycapableswitches.PolicyManager
providestheabilitytocentrallydefineandconfiguretheauthorizationlevelsorpolicies.
NetSightInventoryManagerisanoptionalcomponent,providingcomprehensivenetwork
inventoryandchangemanagementcapabilities.
Model 3: End-System Authorization with Assessment
ThisNACdeploymentmodelimplementsthedetection,authentication,assessmentand
authorizationNACfunctionalitiesforconnectingendsystems.InModel2,endsystemsandend
usersconnectedtothenetworkareauthorizedbasedonthedeviceidentity,useridentity,and/or
locationinformation.Model3extendstheauthorizationdecisioninNACtoone
additional
dimensionthesecuritypostureoftheendsystemasdeterminedfromanassessment.The
assessmentcanbeexecutedthroughagentbasedoragentlesstechniquesandcanidentify
differentpiecesofinformationaboutthedevice,suchanantivirussoftwareconfiguration,
operatingsystempatchesinstalled,softwareapplicationsinstalledand
running,processes
running,servicesconfigured,andregistryvaluesset.
ItisimportanttonotethatitisnotnecessarytoconfiguretheEnterasysNACsolutionto
quarantineendsystemsthatfailassessment.Infact,duringtheinitialrolloutofNAConthe
enterprisenetwork,itishighlyrecommendedthatendsystems
arenotrestrictedaccesstothe
networkinanywaybefore,during,orafterfailedassessment.ThispassiveNACconfiguration
allowstheITadministratortobaselinetheconfigurationofdevicesonthenetworkand
understandthecurrentlandscapeofitsassetswithoutimpactingnetworkconnectivityfor
connectingendsystems.Inthis
configuration,itisnotnecessarytoinformtheendusersthatthey
arebeingassessedorhavefailedassessmentbecausethereislittletonoimpactonnetwork
connectivityduringthisassessment.Endsystemscanbescannedinthebackgroundproviding
thenetworkadministratorwithimportantvisibilityintohowdevices
areconfiguredontheir
network,whileenduserscanutilizethenetworkasdesired.Then,whenthenetwork
administratorisready,theEnterasysNACsolutioncanbeconfiguredwiththeclickofabuttonto
immediatelyrestrictaccessforendsystemsthathavefailedassessment.
Implementation
InModel3,endsystemscanbedetectedandtracked,authenticated,assessed,andauthorizedin
differentwaysdependingonwhetherinlineoroutofbandnetworkaccesscontrolis
implementedintheEnterasysNACsolution.
Out-of-Band NAC
ForoutofbandEnterasysNACdeploymentsutilizingtheNACGateway,NACfunctionsare
implementedinthefollowingway:
Detection‐AsdescribedinModel2.
Authentication‐AsdescribedinModel2.
Assessment‐TheNACGatewaycanleverageeitherlocalassessmentservicesand/orremote
assessmentservicesdeployedonthenetwork.TheNACGatewayʹ
slocalassessmentservices
includeagentlessassessmentwhichcanexecutevariousserversidechecks(whetheranFTP
Vue de la page 29
1 2 ... 25 26 27 28 29 30 31 32 33 34 35 ... 97 98

Commentaires sur ces manuels

Pas de commentaire